The users-ultra plugin prior to 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.
usersultra users ultra membership